Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Andro
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (ve
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to de
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute cal
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user dat
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application cons
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups'
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUser
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions f
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 b
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 be
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ven
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config us
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user ha
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Relea
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release al
Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-20
Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untruste
Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applicati
Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allow
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start em
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific fo
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and be
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bin
Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attac
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attacke
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S
Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started